Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1003029

Опубликовано: 06 мар. 2019
Источник: redhat
CVSS3: 8.8

Описание

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

A flaw was found in the Jenkins Script Security plugin version 1.53. An attacker with Overall/Read permissions is able to escape the sandbox and execute arbitrary code on the Jenkins master JVM. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.4jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.5jenkins-plugin-script-securityWill not fix
Red Hat OpenShift Container Platform 3.6jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.7jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 3.9jenkins-2-pluginsWill not fix
Red Hat OpenShift Container Platform 4jenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsFixedRHSA-2019:073910.04.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-96
https://bugzilla.redhat.com/show_bug.cgi?id=1689873jenkins-plugin-script-security: sandbox bypass in script security plugin

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.9
nvd
больше 6 лет назад

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

CVSS3: 9.9
github
больше 3 лет назад

Sandbox bypass in Script Security Plugin

CVSS3: 9.9
fstec
больше 6 лет назад

Уязвимость компонентов GroovySandbox.java и SecureGroovyScript.java плагина Jenkins Script Security, позволяющая нарушителю выполнить произвольный код

8.8 High

CVSS3